Skip to content

トピトピニュース

Header Image
Author

GitHub

1143 Posts

Featured

Posted byGitHub
[github.com/crewjam/saml] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Posted byGitHub
[org.keycloak:keycloak-core] Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Posted byGitHub
[bitlyshortener] Package discontinued because Bitly lowered the free quota
Posted byGitHub
[baserproject/basercms] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

[com.github.kevinsawicki:http-request] Missing certificate validation

  • Posted inMODERATE
  • Posted byGitHub
  • 05/25/202211/04/2022

OSS Http Request (kevinsawicki/http-request) is missing SSL/TLS certificate validation. The impact is: certificate spoofing. The component is: use this library when https communication. The attack vector is: certificate spoofing.
References

https://nv…

[org.jenkins-ci.plugins:pipeline-maven] XML External Entity processing vulnerability in Pipeline Maven Integration Jenkins Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202209/09/2022

An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a temporary directory’s content on the agent running the Maven build to have Jenkins parse a maliciously craft…

[org.jenkins-ci.plugins:influxdb] Plaintext password storage in Jenkins InfluxDB Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202209/09/2022

Jenkins InfluxDB Plugin Prior to 1.22 stored credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
References

https://nvd.nist.gov/vuln/detail/CVE-2019-1…

[org.jenkins-ci.plugins:gitea] Improper handling of untrusted branches in Gitea Jenkins Plugin

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202209/15/2022

Jenkins Gitea Plugin prior to 1.1.2 did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.
References

https://nvd.nist.gov/vu…

[Microsoft.ChakraCore] Chakra Scripting Engine and ChakraCore Vulnerable to Memory Corruption

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202208/31/2022

Chakra Scripting Engine and ChakraCore are vulnerable to memory corruption due to an out-of-bounds write. The Microsoft advisory for CVE-2021-42279 was modified in August 2022 to include Microsoft.ChakraCore as an affected product.
References

https://…

[org.jenkins-ci.main:jenkins-core] Missing Authorization in Jenkins

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202210/26/2022

FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access control in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-21689
https://www.jenkins.io/security/advisory/202…

[org.jenkins-ci.main:jenkins-core] Improper Authorization in Jenkins

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202210/26/2022

When creating temporary files, agent-to-controller access to create those files is only checked after they’ve been created in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-21693
https://www.je…

[org.jenkins-ci.main:jenkins-core] Missing Authorization in Jenkins

  • Posted inHIGH
  • Posted byGitHub
  • 05/25/202210/26/2022

FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-21695
https://www.jenkins.io…

[apache-airflow] Missing Authentication for Critical Function in Apache Airflow

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202209/21/2022

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, infor…

[org.jenkins-ci.plugins:nuget] XML external entity vulnerability in Jenkins Nuget Plugin

  • Posted inCRITICAL
  • Posted byGitHub
  • 05/25/202209/08/2022

Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
References

https://nvd.nist.gov/vuln/detail/CVE-2021-21658
https://www.jenkins.io/security/advisory/2021-05-25/#SECURITY-2340
http://w…

Posts navigation

Previous Posts 1 … 79 80 81 82 83 … 115 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close